Last updated
What is an OSINT engagement?
An OSINT engagement is a methodical investigation of what's publicly discoverable about your organisation, using only open sources, never touching your systems. Ironbark Cyber answers a specific question you bring us: what could an attacker learn about our executives? What's leaked about us? What risk is hiding in our supply chain? Then we tell you what to remove, monitor or change.
What types of engagement do you run?
- Executive & VIP exposure assessments. What's publicly available about your leadership, board members or high-risk individuals, and what risk does that pose?
- Supply chain & third-party risk. Map upstream and downstream relationships, and surface vulnerabilities in vendors that could become your problem.
- Pre-engagement reconnaissance. The OSINT phase of a red team, M&A diligence, fraud investigation or insider threat enquiry.
- Leaked data & credential exposure. Deep checks across breach corpuses, code repositories, paste sites and underground forums.
- Threat actor profiling. Tracking, attributing and reporting on adversaries targeting your sector.
Why Ironbark Cyber for OSINT?
Our team has been doing offensive reconnaissance professionally for over a decade. We've built and contributed to widely-used OSINT tooling. Ironbark Cyber founder Luke Stephens (hakluke) wrote some of the recon tools the industry runs, taught the methodologies, and applied them at scale across private and public sector engagements. When we say we know what's findable, it's because we built the things that find it.
Each engagement is scoped to your specific question, executed methodically, and reported in a way that's actually useful: sources, evidence, and clear recommendations. Findings frequently feed straight into social engineering pretexts or external network testing when you want the full attack chain tested.
What do we receive?
- A written intelligence report with every finding sourced and evidenced.
- Risk-ranked recommendations: what to remove, what to monitor, what to change.
- An executive summary suitable for the people the findings are about.
- A debrief call, and guidance on ongoing monitoring where it's warranted.
What does it cost?
Fixed-fee, quoted within one business day of a free scoping call. Scope drives price: a focused executive assessment sits at one end, sector-wide threat actor profiling at the other.
FAQ
Frequently asked questions
How much does an OSINT engagement cost?
OSINT engagements are fixed-fee, quoted within one business day of a free scoping call. The price depends on the question you need answered, a single executive exposure assessment scopes very differently from a supply-chain mapping exercise. The quote never changes mid-engagement.
What is OSINT?
OSINT, open-source intelligence, is intelligence gathered from publicly available sources: websites, social media, breach corpuses, code repositories, public records, paste sites and underground forums. An OSINT engagement shows you exactly what an attacker, an investigator or a journalist could uncover about your people, your supply chain and your operations, before they do.
Is OSINT legal?
Yes. OSINT works entirely from information that is already publicly accessible. The same sources available to any attacker. Ironbark Cyber operates under agreed rules of engagement and handles everything we find with the discretion you would expect from a security firm.
What can you find about our executives?
Typically more than anyone is comfortable with: home addresses inferred from property and social data, family details, travel patterns, leaked credentials, and the personal accounts that make convincing pretexts possible. An executive exposure assessment maps it all, then tells you what to remove, monitor or change.
How is OSINT different from a penetration test?
A penetration test actively attacks your systems; OSINT never touches them. It examines what is already exposed publicly. The two work best together. Our reconnaissance frequently feeds pretexts for social engineering and target lists for external network testing.
Contact
Talk to us
Tell us what you're trying to protect, secure or build. We'll come back with a plan.